Runtime health
- HTTP endpoints and expected status
- System services and scheduled jobs
- Disk pressure and host reachability
- Application-specific health checks
Proactive monitoring · evidence before noise
Ophelia watches the boring operational facts continuously, separates a live failure from an old warning, and escalates through the least disruptive channel that will actually reach you.
What she watches
Every check is narrow, observable, and configured for the system it protects. Ophelia does not infer “down” from an empty response when the real answer is “I could not reach it.”
Signal path
A purpose-built check returns a fact, severity, timestamp, and redacted evidence.
The same unresolved condition does not become a new emergency every polling cycle.
Routine items wait for the brief. Warnings reach chat. Critical issues can move to SMS or voice.
Current health and acknowledged history stay distinct, so an old incident cannot masquerade as a live outage.
Noise control
Ophelia respects quiet hours and operating mode. A work-only pipeline notice can wait until work mode; a genuinely critical failure can climb from Telegram to SMS to a call. Each escalation is driven by severity and delivery state, not drama.
Routine facts are collected into a morning or afternoon rundown instead of arriving as scattered pings.
Reply to a recent warning in plain language to mute or correct it. The adjustment is explicit and reversible.
If a language model is unavailable, the verified fact still ships in plain wording. Style may degrade; evidence does not.
Security model
Credential checks consume redacted health summaries—presence, expiry, and logged-out state—not reusable secret material. Outbound messages pass through a final scrubber, and private panels remain loopback-only.
Availability
Endpoints, system services, storage, scheduled jobs, backup freshness, redacted credential health, communications quota, and model spend.
These checks are implemented for configured accounts and require deliberate authorization, identity verification, and per-tenant routing.
Private-network visibility across more owner devices is planned after Tailscale enrollment and machine-level access controls are verified.